The GHZ state in secret sharing and entanglement simulation 
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In this note, we study some properties of the GHZ state. First, we present a quantum secret 
sharing scheme in which the participants require only classical channels in order to reconstruct the 
secret; our protocol is significantly more efficient than the trivial usage of teleportation. Second, 
we show that the classical simulation of an n-party GHZ state requires at least n logj n — 2n bits 
of communication. Finally, we present a problem simpler than the complete simulation of the 
multi-party GHZ state, that could lead to a no-go theorem for GHZ state simulation. 



I. INTRODUCTION 



I The GHZ state (also called cat state) was introduced by Daniel M. Greenberger, Michael A. Horne and Anton 
Zeilinger [l0| as a new way of proving Bell's Theorem [l|. The n-party version of the GHZ state is given by 

71 n 

pH , As the most frequently used multi-party entangled state, the GHZ state has appeared in applications such as 

' nonlocality [T^ , communication complexity 01 and multi-party cryptography ^ . 
^ I Our contribution deals with the GHZ state in two scenarios. In Section [TTl we show that in the context of quantum 
, ^ / secret sharing, the GHZ state can be used to implement an ((71, 7i))-threshold scheme where the reconstruction of 
the secret requires only classical communication and is more efficient than the obvious protocol based quantum 
^-H ■ teleportation. In Section IIIH we show that for the task of classical entanglement simulation, the communication 
^ ' required to simulate an n-party GHZ state is lower-bounded by nlogn — 2n. This is an improvement on the previously 
0^ , known nlog2 n — 3n lower bound 0]. The general question of the feasibility of GHZ simulation is still open and, still 
' in Section urn, we give a necessary condition for the task to be achievable. 

p ; 

O ■ II. SECRET SHARING 

00 ! 

I An (n, t) -threshold secret sharing scheme is a protocol by which a dealer distributes shares of his secret to n players 
I such that, when combining their shares, any subset of t or more players is able to recover the secret, while any subset 
.5^ ■ of less than t players is unable to gain any information on the secret. Classical secret sharing was independently 
, introduced by George Blakley Q and Adi Shamir Following the literature, we denote a quantum threshold secret 
^ ' sharing scheme by ((n,i)) while reserving (n,t) for classical schemes. In quantum secret sharing, it is in general 
5^ , assumed that, in order to reconstruct the secret, the players have access to quantum channels. Here, we concentrate 
on the case where the players do not share quantum channels (they do however have a quantum channel with the 
dealer). There is an obvious way for the players to adapt to this restricted scenario: quantum teleportation enables 
the conversion of any standard quantum secret sharing scheme into one with only classical communication during 
the reconstruction phase. This procedure substitutes each qubit of communication with two bits of communication 
coupled with a pre-distributed maximally entangled two-qubit state: 

I*-) = ^101) -^110). (1) 
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Theorem 1. In the teleportation-based version of a one-qubit secret sharing scheme, " ^ " shared states j^* ) are 
necessary and sufficient for the reconstruction of the secret. 

Proof. Because eaeh participant is potentially the receiver of the secret, each participant must be linked to every other 
participant by at least one disjoint path consisting of states l^*"). Seeing the participants as vertices and the shared 
entanglement as edges, we have that eaeh vertex must have degree > n — 1. Counting the degree at each vertex yields 
a lower bound of n{n — l)/2 for the total number of edges. Since the complete graph, Kn, satisfies our criteria, we 
have the desired result. □ 

If we add to Theorem [T] the requirement that each share of the secret contain a qubit, the total number of qubits 
required for a teleportation-based scheme is n^. In sharp contrast, our protocol requires only a single shared multi- 
party state, each player holding a single qubit, for a total of n qubits. This is sufficient for both the shares and 
the reconstruction. Since quantum memory is one of the most challenging aspects of experimental quantum physics, 
our protocol could lead to interesting implementations. Damian Markham and Barry C. Sanders have recently 
independently proposed a quantum secret sharing scheme which also uses an underlying n-party entangled state and 
only requires classical communication to reconstruct the secret (TTj . Their approach is based on the graph state 
formalism. 

A. Protocol for Quantum Secret Sharing with Classical Reconstruction 

We now present our ((n, n))-threshold Quantum Secret Sharing with Classical Reconstruction (QSS-CR) protocol. 
Suppose the dealer wishes to share the quantum secret state j'l') = a|0) -I- /?|1). 

1. Partial encryption. The dealer chooses uniformly at random x E {0, 1}. If x = 0, he does nothing to I^P) for 
this step. If x = 1, he applies the negation transformation, N: 

Let the resulting state be |*') a'\0) + . 

2. Expansion. The dealer expands j'l'') into an rt-qubit state by creating n — 1 pseudo-copies; the resulting state is: 

I*") =a'|0")+/3'|l") (3) 

3. Distribution. The dealer picks uniformly at random a bit string a; = xiX2 ■ ■ .Xn with ®"^]^ Xi — x. Player i's 
share consists of bit Xi as well as of qubit i of l^*"). 

4. Reconstruction The players decide who will receive the secret; say they agree on player 1. 

• Player i (i = 2, 3, . . . , n) applies the Hadamard transform H to his qubit: 

• Player i (i = 2, 3, . . . , ti) measures his qubit in the computational basis. Let the outcome be y^; this value, 
along with Xi is sent to player 1. 

• Player 1 computes y ~ ®"=9 Hi- If 2/ = 0, he does nothing. If y = 1, he applies Z to his qubit: 

• Player 1 computes x = Xi. If a; = 0, he does nothing. If a; = 1, he applies N to his qubit. The result 
is the reconstructed secret. 
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B. Correctness and Privacy 

We now show that our QSS-CR protocol produces the correct output (Theorem [2]) and is secure against coUusions 
of less than n players (Theorem The proof of the following theorem follows from the properties of the GHZ state. 

Theorem 2. At the end of the QSS-CR protocol, the receiver has the initial quantum state j'l'). 

Theorem 3. In the QSS-CR protocol, any subset of s < n players cannot learn anything about |^'). 

Proof. Without loss of generality, suppose players 1, 2, . . . , n — 1 share their secrets. We now show that their joint 
state is independent of the initial shared secret, \'i>). To do this, first note that the classical bits xi,X2, ■ ■ - Xn-i are 
uniformly distributed over all possible combinations (and independent of everything else) and in particular they reveal 
nothing about x. Next, note that since jvl/") is either ajO") + or /3|0") + (with equal probability), the 

n — 1 players can collaborate to coherently transform their joint system into a tensor product of an unknown 1-qubit 
state and a known n — 2 qubit state. The unknown qubit is in the totally mixed state; it thus does not contain any 
information about j^*). □ 

III. CLASSICAL SIMULATION OF THE GHZ STATE 

It is well known that entanglement gives rise to correlations that are not achievable by spacelike-separated parties 
that are allowed only prior shared randomness In the study of entanglement simulation, we ask: what extra 
resources are sufficient for the parties to produce correlations as if they shared a given entangled state? In the case 
of the simulation of the maximally entangled two-qubit state l^*"), a single bit of communication is sufficient [l^; the 
same result can also be achieved with a single use of a nonlocal box [slfist. In contrast to these important results, 
relatively little is known about the simulation of the GHZ state, in particular it is still an open question whether or 
not simulation with finite communication is possible. 

In Theorem 21 we give a lower bound on the number of classical bits required to simulate an n-party GHZ state. 
Our work improves (by n bits) a previous lower bound of nlog2 n — 3n @; our simple method is new and could provide 
insight into the general task of entanglement simulation. While we still do not have an answer to the question of the 
existence of a simulation protocol, we now know that if a protocol exists, it would require at least nlogn2 — 2n bits 
of communication. The question of the existence of a classical simulation of the GHZ state is addressed in Section [1111 
where we give a necessary condition for a simulation to exist (Theorem [71) . 

A. Lower Bound on the GHZ State Simulation 

Communication complexity is the study of the amount of communication required in order for players to accomplish 
a distributed task (see, for instance §). We are interested here in the model where the complexity is counted as the 
number of bits that must be broadcasted in order for every party to know the exact value of / for a given input. In 
this section, we make links between communication complexity results and entanglement simulation. We first recall 
the following theorem: 

Theorem 4 ([3|)- There exists an n-variable Boolean function f taking as inputs k-bit binary strings (k > \0g2n) 
which, without entanglement, has communication complexity of at least n log2 n ~ n bits while if the parties share 
prior quantum entanglement given as a GHZ state, the communication complexity is n bits. Furthermore, the 
strategy involving quantum entanglement consists of an initial round of local measurements followed by an exchange 
of classical messages. 

We now proceed with our main result of this section. 

Theorem 5. The exact simulation of the n-party GHZ state requires at least nlog2 n — 2n hits of classical communi- 
cation. 

Proof. Let C{n) be the quantity that we wish to lower bound. Suppose it is possible to simulate a GHZ state. Then 
the communication complexity task of Theorem [H could be achieved by simulating the GHZ state with C{n) classical 
bits and then communicating n classical bits as in Theorem [4l Specifically: 

C{n) + n > n log2 n ~ n 

C(n) > nlog2 n — 2n □ 
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B. A Necessary Condition for GHZ State Simulation 



As mentioned, the possibility of GHZ state simulation with bounded communication is an open problem. Here, we 
give a step towards solving this problem: a simple communication complexity task that is possible to solve if GHZ 
entanglement simulation is possible. This implies that if we can somehow show that this simple task is impossible to 
accomplish, then the general task of GHZ simulation would also be impossible. We believe that this task somehow 
captures the essence of GHZ state simulation, and would be surprised if it turns our that the task is achievable, 
whereas the general GHZ state simulation is not. Our new task can easily be generalized to n parties and is given by 
the following: 

Problem 6. Let players Pi, P2 and P3 share a random variable A where < A < 1 (i.e. the players share unbounded 
random variables). A dealer gives each player an angle, 61, 62 and 0^ respectively. The goal is for the players 
to individually (without communication) send a message of constant length to a receiver who, after receiving all 
three messages, must output the value 1 with probability exactly cos^(0i + ^2 + ^3) o'^c^ with probability exactly 
sin2(0i+ 02 + ^3). 

Theorem 7. The exact classical simulation of the GHZ state cannot be achieved if no protocol for Problem\^ exists. 

Proof. We show the contrapositive of the statement: if an entanglement simulation protocol for the n-party GHZ 
state exists, then a protocol for Problem [S] exists. 

Consider the following scenario: the participants initially start with a three-party GHZ state. Each party receives 
as input an angle 61 , 62 and ^3 , respectively. Each participant i applies 

e-'vcr), (6) 

followed by a Hadamard transform, H . The resulting state just before the Hadamard transform is: 

1 „2(ei+e2+e3)V^ 
-^1000) + — ^1111). (7) 

Each participant measures in the computational basis and outputs the result. A simple calculation reveals that the 
sum of the outputs is even with probability cos^(0i + O2 + ^3), while the sum of the outputs is odd with probability 
3111^61+62+63). 

Thus, any protocol to simulate the GHZ state must be able to simulate the above scenario. A simulation usually 
involves bounded classical interaction; in order to achieve the goal of Problem [6l all communication paths are followed 
simultaneously, with the receiver choosing the final correct path and computing the parity of the player's output 
bits. □ 



IV. CONCLUSION AND DISCUSSION 



We have seen how the GHZ state gives rise to an elegant and efficient quantum secret sharing protocol with purely 
classical communication during the reconstruction phase. Because we have significantly lowered the quantum memory 
requirements, our protocol may be within reach of experimental implementations. Wc have also shown that if the 
classical simulation of the GHZ state is feasible, then it requires at least ?? log2ri — 2n bits of communication. The 
question of whether this simulation can really be done is still open, but we have given a potential method to prove 
the impossibility: if we can show that Problem [5] is impossible to achieve, then we will know that the GHZ state 
simulation is impossible to achieve perfectly with bounded communication. If it turns out the Problem[S]is achievable, 
then we will have evidence of the possibility of GHZ state simulation. 
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